<?php
require_once 'inc_security.php';
$action = getValue('action','str','POST','');
switch($action){
    case 'add_reply':
        $rep_comment_id = getValue('rep_comment_id','int','POST',0);
        $rep_content = getValue('rep_content','str','POST','');
        $admin_id = getValue("user_id","int","SESSION");
        $admin_cur = db_first('SELECT * FROM admin_users WHERE adm_id = '.$admin_id);
        $rep_name = $admin_cur['adm_name'] == '' ? $admin_cur['adm_loginname'] : $admin_cur['adm_name'];
        $rep_email = $admin_cur['adm_mail'] == '' ? $admin_cur['adm_loginname'].'@maxmobile.vn' : $admin_cur['adm_mail'];
        $db_in_rep = new db_execute('INSERT INTO comments_reply(rep_content,rep_name,rep_email,rep_comment_id,rep_admin,rep_date)
                                             VALUES("'.$rep_content.'","'.$rep_name.'","'.$rep_email.'",'.$rep_comment_id.','.$admin_id.','.time().')');
         if($db_in_rep->total) {
            echo '1';
         }else {
            echo '2';
         }
    break;
    case 'del_reply':
        $rep_id = getValue('rep_id','int','POST',0);
        $db_out_rep = new db_execute('DELETE FROM comments_reply WHERE rep_id = '.$rep_id);
         if($db_out_rep->total) {
            echo '1';
         }else {
            echo '2';
         }
    break;
}
?>